
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@squawk/geo
Advanced tools
Geospatial utilities: great-circle distance, bearing, midpoint, destination point, and polygon containment
Geospatial utilities for aviation applications: great-circle distance, initial bearing, midpoint, destination point, and polygon containment.
Part of the @squawk aviation library suite. See all packages on npm.
npm install @squawk/geo
Exports are grouped by domain namespace to keep call sites self-documenting:
import { greatCircle, polygon } from '@squawk/geo';
// Great-circle calculations (WGS84 lat/lon in decimal degrees)
const distNm = greatCircle.distanceNm(40.6413, -73.7781, 33.9425, -118.4081);
const brgDeg = greatCircle.bearing(40.6413, -73.7781, 33.9425, -118.4081);
const both = greatCircle.bearingAndDistance(40.6413, -73.7781, 33.9425, -118.4081);
const mid = greatCircle.midpoint(40.6413, -73.7781, 33.9425, -118.4081);
const dest = greatCircle.destination(40.6413, -73.7781, 270, 100);
// Polygon containment with bounding-box pre-filter
const ring: number[][] = [
[-118.42, 33.93],
[-118.42, 33.96],
[-118.38, 33.96],
[-118.38, 33.93],
[-118.42, 33.93],
];
const box = polygon.boundingBox(ring);
if (polygon.pointInBoundingBox(-118.4, 33.945, box)) {
if (polygon.pointInPolygon(-118.4, 33.945, ring)) {
// point is inside the polygon
}
}
[lon, lat] coordinate-pair convention for each ring pointFAQs
Geospatial utilities: great-circle distance, bearing, midpoint, destination point, and polygon containment
The npm package @squawk/geo receives a total of 29 weekly downloads. As such, @squawk/geo popularity was classified as not popular.
We found that @squawk/geo demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.